Privacy Policy
What we collect, why, and what we refuse to do with it.
Last updated 13 August 2026.
The short version
- We do not train models on your code, and we do not sell your data to anyone.
- The desktop application in local mode sends us nothing. No account, no telemetry, no transcripts.
- Your model provider — Anthropic or OpenAI — receives your prompts and your code directly under your own agreement with them. We are not in the middle of that.
- Secrets you store with us are encrypted so that no route returns their value — not to an administrator, not to us.
Who is responsible
Caret AGI is the controller for the account information described below. For the content inside your boxes — your repositories and transcripts — you are the controller and we are a processor; the terms of that are in our Data Processing Addendum.
What we collect
If you only use local mode
Nothing. There is no account, no analytics and no crash reporting in the desktop application. Your sessions, transcripts and settings are files on your own disk.
If you use the cloud
- Account — your email address, name and organisation, held by WorkOS, our identity provider. We store the identifiers they give us and a display name; we never see your password.
- Billing — handled by Dodo Payments, our merchant of record. They collect your payment details and billing address. We never see a card number. We store a customer identifier, your plan and your subscription state.
- Usage — for each of your boxes, when it was awake and how large it was. This is what an invoice is argued from, so it is append-only.
- Content in your boxes — repositories, worktrees, transcripts, and anything the agent writes. Stored on the box’s own disk.
- Operational logs — request times, error messages and box lifecycle events. These name accounts and boxes; they do not contain your source code or your prompts.
What we do with it
We run the service, bill you for it, keep it secure and answer you when you write to us. That is the whole list. We do not profile you, we do not advertise, and there is no automated decision-making with a legal effect.
Our lawful bases, where that framing applies: performing our contract with you (running the service and billing), our legitimate interests (security, abuse prevention, keeping the service working), and legal obligation (tax records).
Who else touches it
Only the subprocessors listed in the DPA — currently our cloud provider, our identity provider, our payment provider and our database provider. Each is contractually bound and each is named there rather than described vaguely as “service providers”.
Your model provider is not our subprocessor. Your prompts and code go to Anthropic or OpenAI from the box under your own credential and your own agreement with them.
Your own computer
The host bridge lets an agent running in a box reach files on your Mac. It is off until you turn it on. When it is on it reaches only Downloads, Desktop and Documents plus any folder you add — and never your SSH keys, keychains, cloud credentials or browser profiles, including through a symlink placed inside a folder you did share. Nothing it reads is sent to us; it goes between your machine and your box.
How long we keep it
- Box contents — until you delete the box or close your account, then within 30 days.
- Account records — while your account is open, then 90 days.
- Billing records — as long as tax law requires, typically seven years.
- Operational logs — 30 days.
Where it is
Boxes and the control plane run in the United States today. If you are in the EEA or the UK, that transfer relies on Standard Contractual Clauses, which are incorporated by the DPA.
Security
Everything is encrypted in transit. Secrets are encrypted at rest with a key per team, and the API has no route that returns a secret’s value to anybody. Credentials we issue are revocable and revoking one takes effect on the next request rather than when it expires. Access to production is limited to the people who run it.
Your rights
Depending on where you live you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to complain to a supervisory authority. Write to privacy@caretagi.com and we will answer within 30 days. We do not charge for this and we will not make it difficult.
Children
Caret is not for anybody under 16, and we do not knowingly collect their data.
Cookies
This site sets one cookie, which holds your sign-in session. There is no analytics, no advertising and no third-party tracking, which is why there is no consent banner.
Changes
We will email account holders before a material change takes effect. The date at the top is changed by hand.